New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

search.lt news

search.lt presents newest links more »

Japan passes info-tech law to create e-nation

Japan has moved a step closer to Prime Minister Yoshiro Mori's goal of creating an e-nation when parliament approved a bill adopting the Information Technology (IT) revolution as a national goal. more »

The Problems with Online Media in Lithuania

New type of media came to Lithuania. Now it is rather controversial and there are a lot of legal and moral problems to be discussed. more »

search.lt news

search.lt presents newest links more »

Intellectual property rights high on Baltic agenda

Latvian, Lithuanian and Estonian senior government officials, judges and intellectual property specialists gathered in Riga last week more »

Vote-Auction.com Back Online

A Web site offering citizens a chance to auction their vote to the highest bidder is back online today using a pure Internet protocol (IP) address. more »

Philippines Tech Industry Looks To Life After 'Love Bug'

International attention was inadvertently focused on Manila's software community earlier this year when the most damaging computer virus ever released crippled computers worldwide. more »

Ericsson to start developing 3G mobile networks in Estonia

Ericsson's Estonian operation Wednesday launched a unit for third generation mobile network planning that will be designing new networks primarily for the international market. more »

RealNetworks, Sony update audio software

Web media streaming giant RealNetworks has teamed with Sony to introduce a new version of its RealAudio technology, which allows sound to be broadcast via the Internet. more »

3Com lets Audrey out the door

3Com lifted the curtain Tuesday on Audrey, a countertop appliance designed to give gadget-happy families a quick way to surf the Web and shoot off email. more »